What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current set of supported scanner adapters and signing backends: verify against project documentation
- Replication targets and authentication provider list: confirm against project documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Harbor is a registry, and the security features are consequences of controlling the place where artifacts live. It stores OCI images and other OCI artifacts such as Helm charts, organizes them into projects that carry their own membership and policy, and authenticates users against a local database, LDAP or an OIDC provider, with robot accounts for machine access.
Scanning is delegated rather than built in. Harbor defines a scanner adapter interface and ships with Trivy wired up by default, with other engines pluggable behind the same API. Scans run on push or on a schedule, and results feed a deployment security policy that can prevent pulls of images above a severity threshold, which turns a report into an actual control because the registry is the only path to the image. Content trust works the same way: Harbor verifies Cosign signatures and can require that unsigned images not be pulled. Around that sit the controls that keep a registry manageable: replication rules, tag retention, tag immutability to stop a tag being silently repointed, project quotas, garbage collection, and an audit log.
Where it fits
Harbor is infrastructure, installed and operated by a platform team, typically on Kubernetes through the official chart. It sits between your build pipeline and your runtime: builds push here, clusters pull from here, and proxy cache projects let it stand in front of public registries so external images arrive through a point you control and scan. It needs persistent storage, a database, and someone who keeps it patched, because a registry outage stops deployments.
Strengths
- Blocking pulls on scan results or missing signatures is enforcement at a choke point, not an advisory finding in a dashboard.
- Proxy cache projects give you a single controlled ingress for third party images, which shrinks supply chain exposure considerably.
- Project scoped RBAC and robot accounts map cleanly onto multi team environments without one shared credential.
- Pluggable scanner adapters mean you are not locked to one vulnerability engine.
Limitations
- Harbor does not scan anything itself. The quality of your findings is entirely the quality of the adapter you configure.
- It is stateful infrastructure with real availability requirements, and running it well takes more attention than a managed registry.
- Scope stops at the registry boundary: no runtime visibility, no admission control in the cluster, no posture assessment.
Who it suits
The right answer for organizations that need a private registry they operate themselves, whether for air gapped environments, data residency or control over the supply chain, and that have a platform team comfortable running stateful services. Overkill for a small team content with a managed cloud registry that already scans images.
Used Harbor? Recommend it under your own name and title.
Recommend this tool